Blurred Lines of Cyber Threat Attribution: The Evolving Tactics of North Korean Cyber Threat Actors

2025-08-10 Zscaler

https://media.defcon.org/DEF%20CON%2033/DEF%20CON%2033%20villages/DEF%20CON%2033%20-%20Adversary%20Village%20-%20Seongsu%20Park%20-%20Blurred-Lines-of-Cyber-Threat-Attribution.pdf

Attachments

DEF20CON203320-20Adversary20Village20-20Seongsu20Park20-20Blurred-_scTIk12.pdf (5 MB)

Seongsu Park’s DEF CON material examines how North Korean cyber operations have evolved from broad umbrella labels into multiple specialized clusters with overlapping tools, infrastructure, and mission sets. The slides describe Lazarus-linked history, Kimsuky expansion, and operational specialization across financial crime, espionage, and intelligence collection, arguing that TTP-based clustering is needed for more accurate attribution. One case highlights PEBBLEDASH activity where Lazarus-linked malware traits appeared alongside Kimsuky-associated C2 infrastructure, including address.linkedin.p-e[.]kr and phishing infrastructure using shortened URLs and naverdomain-themed domains. The material also details post-exploitation behaviors such as PowerShell command execution, HazyLoad proxy use, Ngrok tunneling, RDP account creation, and Chrome Remote Desktop installation, showing why full-chain analysis matters when DPRK groups share or reuse tools.

Indicators of Compromise

Type Value First Seen Last Seen
URL https://buly.kr/uTnE2J 2025-08-10 2026-04-07
URL https://buly.kr/FLXvf9J 2025-08-10 2026-04-07
URL http://address.linkedin.p-e.kr/… 2025-08-10 2026-04-07
URL https://buly.kr/ESy8l3Z 2025-08-10 2026-04-07
DOMAIN buly.kr 2025-08-10 2026-04-07
DOMAIN address.linkedin.p-e.kr 2025-08-10 2026-04-07
DOMAIN secure.naverdomain.r-e.kr 2025-08-10 2026-04-07
URL http://gsegse.dasfesfgsegsefsed… 2025-05-19 2026-04-07
DOMAIN gsegse.dasfesfgsegsefsede.o-r.kr 2025-05-15 2026-04-07
URL http://gtfydu.surfnet.ca/index.… 2025-04-11 2026-04-07
DOMAIN gtfydu.surfnet.ca 2025-04-11 2026-04-07
HASH ca93591a9441a2ade70821f67292d982 2025-03-04 2026-04-07
HASH 9e94126e8a26efd10b2a5b179d64be90 2025-03-04 2026-04-07

Related Actors

Related Reports

« Back